Home Articles Get your free assessmentComing soon

Author: Mission Defend Staff

  • The First 24 Hours: What to Tell Your Congregation

    The First 24 Hours: What to Tell Your Congregation

    It is 4:15 on a Thursday when the bookkeeper realizes something is wrong. That morning she got a notification about a sign-in to the church email account from a city none of you have visited, and now, in the mailbox settings, there is a forwarding rule she did not create.

    By 5:30 the person who helps you with computers has confirmed it: someone else has been in that mailbox for at least eleven days. It holds the counting team’s spreadsheets, scanned checks, the pastoral care list, and four years of correspondence.

    The pastor asks the question every leader asks at this moment, and it is the right one:

    What do we tell people?

    The answer that feels safest — wait until we understand it fully, then send something carefully worded — is almost always the wrong one. Not because the caution is unreasonable, but because of how congregations actually respond to bad news.

    People forgive the incident. They do not forgive the silence

    Congregations are generally forgiving about the incident itself. They understand that a church has two staff and a volunteer treasurer, that email accounts get compromised at corporations with security teams, that nobody was careless in a way that deserves punishment. Most members have clicked something they shouldn’t have.

    What they don’t forgive is finding out late, finding out from somewhere else, or reading a message obviously written to limit liability rather than to inform. A member who learns three weeks later that their giving records were exposed doesn’t think these things happen. They think they knew and didn’t tell me, and that attaches to the leadership permanently.

    The reputational damage from a slow, defensive, lawyer-flavored message is usually larger than the damage from the incident itself. The incident is a thing that happened to you. The silence is a thing you chose.

    What you must know before you speak, and what you can say anyway

    Twelve hours in, you will not know much. Not which records were accessed, not whether anything was downloaded, not whether member data will be misused. Those answers can take weeks.

    Here is the reframe that unlocks the whole problem. There are three things you can almost always say honestly within hours, and they are the three things people actually want:

    What happened, in the plainest terms. Not the technical mechanism — someone gained access to one of our email accounts is enough.

    What you are doing about it. You locked the account, brought in help, and are reviewing what was in there. All true within the first afternoon.

    What you want them to do. This is the part people scan for, and the part most notices bury.

    You don’t need the full scope to say those three things. What you should have before you speak is confirmation from someone competent that an incident occurred and that the immediate hole is closed. Announcing a breach that turns out to be a misconfigured setting is its own kind of damage.

    One constraint worth knowing. All 50 states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands have laws requiring notification when certain kinds of personal information are exposed — and what counts as personal information, what triggers the duty, how long you have, what the letter must say, and whether a state attorney general has to be told all differ materially from state to state. There is no single national deadline or rule. Ask your attorney what applies to you before the formal notice goes out. Nothing here is legal advice.

    Hours, then days: two different messages

    Separate the two communications in your mind and the timing problem largely dissolves.

    The holding statement goes out within about 24 hours: what happened, what you’re doing, what to watch for, and when they’ll hear from you next. Its job is to make sure nobody learns this from a rumor. The full notice goes out in days, once you know the scope — specific about what was and wasn’t affected, carrying any formal notification your attorney says is required.

    A holding statement you can adapt:

    Subject: An important notice from [Church Name] Dear friends, I’m writing about something that happened here this week, and I want you to hear it from us rather than anywhere else. On Thursday we discovered that an unauthorized person had access to one of our church email accounts. We have locked that account, changed the passwords, and brought in outside help to determine exactly what was accessed and when. We do not yet know the full extent of what was in that mailbox or whether any of it was taken. That review is underway, and I would rather tell you what we know today than wait until we know everything. What we’re asking you to do. Please be cautious about any message that appears to come from the church over the next several weeks — anything asking you to give, click a link, update payment details, or send money or gift cards. The church will never contact you asking for payment, gift cards, banking details, or a password. If you receive something like that, call the office at [number] before you act on it. We will not be offended by the call. This happens to organizations far larger than ours, and what matters now is how we respond. I will write again by [specific date] with what we’ve found. If you have questions before then, call me directly at [number]. [Name] [Role], [Church Name]

    Notice what it doesn’t do: speculate, promise nothing was taken, or apologize in a way that assigns fault to a person. And it sets a specific date for the next message — the easiest way to buy time honestly.

    The follow-up, several days later:

    Subject: Update on the email incident at [Church Name] Dear friends, On [date] I wrote about unauthorized access to one of our church email accounts. Here is what we now know. The account was accessed between [date] and [date]. The mailbox contained [describe plainly: correspondence, some giving records, and documents containing member names and addresses]. We have [no evidence that / evidence that] this information was copied or misused. If your information was affected, you are receiving a separate letter with specific steps, including [credit monitoring / what to watch for]. If you did not receive that letter, our review indicates your information was not in the affected account. What we have changed. Every church account now requires a second step to log in beyond the password, so a stolen password alone is no longer enough. We have reviewed every account for unauthorized forwarding rules, and our board adopted a written security policy on [date]. What we’re still asking of you. Keep treating unexpected messages about the church with suspicion — anything about giving, payments, or account details, and especially anything referring to this incident. Call the office to check. We would much rather field the call. We have reported this to [law enforcement / the appropriate authorities] and are following the notification requirements that apply to us. I’m grateful for the grace you’ve shown this week. If you’d like to talk, my number is [number]. [Name]

    Who speaks, and how it reaches the people least likely to read email

    Decide the voice before you need it. It should be the senior pastor or the board chair — one person, named, with a real phone number in the message. An unsigned notice from “the church office” reads as institutional distancing at exactly the wrong moment.

    Then use every channel, because they reach different people:

    Email, to everyone you have an address for. Fastest, and the record of what you said.

    The website. A short dated notice on the front page. This is where members send their adult children, and where anyone who hears a rumor will check.

    From the front, on Sunday. Two minutes, in plain language, not buried in announcements. Members who hear their pastor say it out loud experience it entirely differently than members who read it, and it visibly signals that the leadership is not hiding. Put a printed copy in the bulletin too.

    A phone tree. The one that gets skipped, and the one that matters most.

    Here is the uncomfortable arithmetic. The members most likely to be targeted by follow-on scams are your older members — the FBI logged 201,266 complaints from victims aged 60 and over in 2025, a 37% increase over 2024, and $7.748 billion in losses, which was up 59% in a single year. The members least likely to read an emailed notice are very often the same people. A written notice reaches the people who need it least.

    So build a short list of members who don’t use email reliably, split it among your deacons, elders, or care team, and call them. The script is three sentences: Something happened with the church’s email. Nobody needs to do anything. But if anyone contacts you claiming to be from the church and asks for money or account details, hang up and call the office.

    Twenty people making six calls each covers a congregation in an evening.

    The instruction that stops them being victimized twice

    Attackers who have been inside a mailbox for eleven days know your members’ names, your pastor’s writing style, your giving cycle, and the fact that you just announced a breach. The second wave is often more profitable than the first: a message that references the incident, expresses concern, and asks the member to “verify” something.

    So give the instruction in a form people can remember under pressure:

    The church will never contact you asking for money, gift cards, banking details, passwords, or account verification — by email, text, or phone. If anyone does, it isn’t us. Hang up or delete it, and call the office on the number in the bulletin.

    Put that sentence in the holding statement, the follow-up, the bulletin, and the phone script, and repeat it in the newsletter a month later. It’s permanent congregational hygiene that happens to be most urgent right now.

    What not to do

    Don’t minimize. “A minor issue with one of our systems” is the phrase that gets quoted back to you when the scope turns out to be larger. Describe it accurately, or as still under review — never smaller than it is.

    Don’t name the staff member. Not in the notice, not from the pulpit, not in conversation. That person is already carrying it, and naming them tells everyone else in your organization that reporting a mistake gets you publicly identified — precisely the behavior you cannot afford. If your board asks who, the answer is: a member of our team was targeted by a convincing message, and they reported it quickly, which is what limited this.

    Don’t promise it can never happen again. You can’t deliver it, and it’s what people remember if there’s a second incident. Say what you have changed instead — stronger, and true.

    Don’t go quiet because of legal advice. Counsel should review the wording of anything you send — that is what counsel is for, and formal notification has requirements you should not guess at. But there is a difference between have a lawyer read this before it goes out and say nothing until the lawyer is comfortable, and the second can run for weeks. Bring your attorney in on day one and give them a deadline. Saying nothing is not neutral; it is a choice, and its consequences compound daily.

    Don’t let the first Sunday pass in silence. If the congregation is in the building and nobody mentions it, you have communicated something.

    What to do this week

    You almost certainly are not in an incident right now, which is exactly why this is the week.

    Write two things and put them in a shared folder labeled clearly enough that a panicking person can find it: the name and mobile number of whoever will speak publicly if this happens, and a draft holding statement — adapt the one above in fifteen minutes by filling in the brackets.

    Then build the phone-tree list: which members don’t use email, and who calls them. On the worst day, that list is the difference between reaching your congregation and merely emailing it.

    Forty-five minutes, and the first 24 hours stop being improvised.

    The best time to work all of this out is before you need it. MissionDefend’s free assessment asks plain-English questions about how your church handles email, donations, member data, and accounts, then hands back a baseline score and a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, Data Breach Response: A Guide for Business; National Conference of State Legislatures, Security Breach Notification Laws; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • A One-Page Cybersecurity Policy Your Board Can Approve on a Tuesday

    A One-Page Cybersecurity Policy Your Board Can Approve on a Tuesday

    There is a binder on a shelf in the church office. The spine says Information Security Policy. Someone downloaded it in 2019, printed it, added tab dividers, and put it on the shelf, where it has remained.

    It is forty-one pages long. It references a Chief Information Security Officer, a quarterly vulnerability management cadence, and a data classification scheme with four tiers. The church has two full-time staff and a volunteer treasurer.

    Nobody has opened it. Not once. If you asked the office administrator what the policy says about wire transfers, she would tell you honestly that she has no idea.

    That binder is not neutral. It is worse than having nothing, because it lets everyone believe the question has been handled.

    The forty-page policy fails for a reason that has nothing to do with its contents

    The contents are usually fine. Somebody competent wrote them. The problem is structural.

    A policy is not a legal artifact. It is an instruction to human beings about what to do on a Tuesday afternoon when an email arrives asking for a payment change. If the instruction is on page 27 of a document nobody has read, it does not exist. The staff member acts on instinct instead, and instinct is exactly what the attacker is designing for.

    Long policies also fail in the other direction. They contain commitments the organization cannot keep — quarterly access audits, annual penetration testing, a security awareness training program — and once a policy contains one thing you obviously aren’t doing, the whole document loses its authority. People stop treating any of it as real.

    A single page that six people actually follow beats a binder that nobody opens. That is the whole argument, and it holds in organizations far larger than yours.

    So here is the page.

    The page

    Copy this. Change the bracketed parts. Do not add to it — the length is the feature.

    “`
    [CHURCH NAME] — INFORMATION SECURITY POLICY
    Adopted by the Board on [DATE]. Next review: [DATE + 1 YEAR].
    Policy owner: [NAME, ROLE].

    1. RESPONSIBILITY The Board is responsible for this policy. [NAME] is responsible for carrying it out and reports to the Board once a year on whether we are doing what this page says.
    1. MULTI-FACTOR AUTHENTICATION Multi-factor authentication is required on: church email, online banking, the giving/donation platform, the church management system, the payroll system, the website host, the domain registrar, and all social media accounts. No exceptions without written Board approval.
    1. VERIFYING MONEY Any request to send money, change bank details, change payroll direct deposit, or pay a new or altered invoice is verified by voice, on a phone number we already had on file — never a number supplied in the request — before the payment goes out. This applies however the request arrives, including from someone inside the organization.
    1. INDIVIDUAL LOGINS Every person has their own login. Logins and passwords are not shared, not with staff, not with volunteers, not with family members. Passwords are stored in the approved password manager, not on paper, in a spreadsheet, or in email.
    1. WHEN SOMEONE LEAVES When any staff member or volunteer stops serving in a role, their access to every account and building is removed within 14 days. [NAME] runs this from the account inventory and confirms it in writing. This applies to everyone, including clergy and Board members.
    1. BACKUPS Church data — financial records, member records, and documents — is backed up automatically, with at least one copy the church controls and that cannot be altered from a staff computer. Once a year we restore a real file from backup to prove the backup works, and note the date it was tested.
    1. IF SOMETHING LOOKS WRONG If you think you clicked a bad link, entered a password on the wrong page, sent money to the wrong place, or noticed anything unusual in an account: stop, and tell [NAME] and [BACKUP NAME] immediately, by phone. Do not wait to be sure. If money has moved, we call the bank first and report to the FBI at ic3.gov the same day.
    1. NO PENALTY FOR REPORTING No one will be disciplined, dismissed, or embarrassed for reporting a mistake or a suspicion, including their own mistake, and including after money has been lost. Reporting quickly is the behavior this church wants. Hiding a mistake is the only thing that gets anyone in trouble.
    1. REVIEW The Board reviews this policy once a year, on or before [DATE]. “`

    That is the entire policy. It fits on one sheet, single-sided.

    What each clause is doing, so you can defend it

    Your board will ask about some of these. Here is the one-sentence answer for each.

    Responsibility. A policy with no name attached is a wish; naming one person and one annual report is what turns it into something that actually happens.

    Multi-factor authentication. Multi-factor authentication — MFA — is the extra step after your password: a code, a tap on your phone, a key. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks, and naming the specific systems matters because churches routinely turn it on for email and forget the giving platform, which is the one holding donor card details.

    Verifying money. This is the single clause most likely to save you real money, because the fraud that actually hits churches is a convincing email asking for a payment change; a thirty-second phone call to a number you already had defeats every version of it.

    Individual logins. Shared logins make it impossible to know who did what, impossible to remove one person’s access without disrupting everyone, and impossible to use MFA properly.

    When someone leaves. Old accounts are the quietest risk you have — nobody is watching them, and their passwords are often years old and reused elsewhere; a defined window turns “we should get around to that” into a date. CISA’s guidance for small organizations puts it plainly: develop procedures addressing changes in user status, and eliminate shared and unused accounts.

    Backups. A backup you have never restored is a theory, and the annual restore test is what converts it into a fact — this is also the clause that determines whether a ransomware incident is a bad week or an extinction event.

    If something looks wrong. Most losses become large because somebody waited; naming two people and requiring a phone call removes the ambiguity about who to tell and how.

    No penalty for reporting. Speed is the only thing that reliably recovers money, and speed depends entirely on whether a frightened person feels safe telling you within the hour rather than on Monday.

    Review. A date on the page is what stops this becoming the 2019 binder.

    Getting it adopted on a Tuesday

    The mistake is presenting this as a debate. It is not a debate; it is a housekeeping item that happens to be important.

    Put it on the consent agenda. Consent items are approved as a block without discussion unless a member pulls one. Circulate the page with the board packet a week ahead, with a two-sentence cover note: This replaces our existing information security policy. It is one page so that staff and volunteers will actually follow it. Most boards will pass it without comment, which is the correct outcome.

    Name the owner before the meeting, not during it. An unassigned policy will sit for a year. Ask the person first, privately, so the name in the document is already agreed.

    Set the review date as a real date. Not “annually.” A date, in the calendar, on the same board meeting each year.

    Record it in the minutes. This is the part people skip, and it is the part that matters most beyond the security question.

    Boards of nonprofit organizations carry a duty of care — the general obligation to act with the attention a reasonably prudent person would apply to the organization’s affairs. The specifics vary by state and by your governing documents, and this is not legal advice; ask your attorney what applies to you. But the general shape is consistent: what a board can demonstrate matters. A minute that reads the Board adopted the Information Security Policy, assigned responsibility to the Business Administrator, and set the annual review for the March meeting is evidence that the board considered the risk and acted. A verbal agreement that somebody should look into cybersecurity is not.

    Give a copy to every person it applies to. Staff, yes — but also the volunteer who runs the website, the volunteer counting team, the person with the Facebook password. One page can be handed to someone in a hallway. Forty-one pages cannot.

    Policy without practice is theatre

    Here is the honest limitation. Adopting this page does not mean your church is prepared. It means your church has written down what it intends to do.

    The gap between those two things is real, and it shows up under pressure. The staff member who has read clause 3 in a board packet is not the same as the staff member who has actually made the verification call once and knows it takes thirty seconds and is not awkward. The person named in clause 7 is not ready until they have said the words out loud in a room, with a scenario in front of them.

    The way to close that gap is a tabletop exercise — a short, low-stakes practice run where you talk through a realistic incident around a table and find out who would actually do what. It takes under an hour and it is the subject of its own post in this series. If you adopt the policy and never practice it, you have documentation. If you adopt it and practice it once a year, you have a response.

    Do the page first anyway. Documentation you follow beats intention you never wrote down.

    What to do this week

    Copy the page above into a document, fill in the five bracketed fields — church name, policy owner, backup contact, adoption date, review date — and email it to whoever assembles the board packet with a request to add it to the consent agenda.

    Then, separately, check one thing before the meeting: whether MFA is actually turned on for the giving platform and the church management system, not just email. If it isn’t, you will want to know that before you sign a document saying it is required.

    Thirty minutes, no budget, and your board has a defensible record by the end of the month.

    If you would like something concrete to bring to the same board meeting, MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first — useful as the evidence behind the annual report clause 1 asks for.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Cybersecurity and Infrastructure Security Agency, Cyber Essentials Starter Kit; Microsoft, mandatory multifactor authentication guidance; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • If You Lose Member Data, Who Do You Have to Tell?

    If You Lose Member Data, Who Do You Have to Tell?

    It’s a Monday. The office administrator can’t get into her email, and when she finally does, the sent folder contains forty messages she didn’t write.

    Or: the laptop was in the back of the car outside the hospital, and now it isn’t.

    Or: someone calls to say the church’s membership spreadsheet is on a website they’ve never heard of.

    Whatever the route, you now stand in a specific place, and the question in the room is not technical. It is: do we have to tell people?

    The honest answer is: probably, sometimes, and it depends on facts you don’t have yet. Which is deeply unsatisfying — so this post explains the general shape of how these laws work, so you can recognize the situation and act fast enough to handle it properly.

    Everything below is a description of how these rules generally work. It is not legal advice. Requirements vary substantially by state, and you need a lawyer — early.

    These laws are not just for corporations

    Start here, because this is the assumption that gets churches into trouble.

    The National Conference of State Legislatures summarizes the landscape plainly: “All 50 states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands have laws requiring private businesses, and in most states, governmental entities as well, to notify individuals of security breaches of information involving personally identifiable information.”

    Nonprofit status is not, by itself, an exemption. These statutes are generally drafted around whoever holds the data rather than around a particular tax classification. Whether a specific state’s law reaches your specific organization is a question with a real answer, and only a lawyer licensed in that state can give it to you. But do not walk into it assuming your 501(c)(3) letter is a shield. It isn’t designed to be one.

    What actually triggers a notice

    Here is the most useful thing in this article, and the part most people have backwards.

    Not every exposure of personal information triggers a notification duty. These laws generally attach to specific, defined categories of data — and a name plus an email address, on its own, very often isn’t one of them.

    NCSL describes the common structure: these laws typically contain “definitions of ‘personal information’ (e.g., name combined with SSN, drivers license or state ID, account numbers, etc.); what constitutes a breach (e.g., unauthorized acquisition of data); requirements for notice (e.g., timing or method of notice, who must be notified); and exemptions (e.g., for encrypted information).”

    In practice, the categories that most commonly appear across state definitions are a person’s name combined with one or more of:

    • Social Security number
    • Driver’s license or state identification number
    • A financial account, credit card, or debit card number, usually together with whatever code would let someone use it
    • In a growing number of states, medical or health insurance information, biometric data such as a fingerprint, or the username and password to an online account

    Look at that list against what your church actually holds. Your membership directory of names, addresses, and emails is sensitive and worth protecting — but its exposure may not trigger a statutory notice. Your payroll file, your background-check drawer, and your donation records with bank account details almost certainly could.

    That distinction is not a reason to relax. It’s a reason to know precisely where your organization keeps the high-consequence categories, before anything goes wrong.

    The obligation usually follows the person, not the church

    This surprises people, and it matters for churches more than for most small organizations.

    These laws are generally written to protect residents of that state. So the question is usually not “which state is the church in?” but “where do the affected people live?”

    A congregation with members who retired to Florida, a college student in another state, and a missionary family supported from a third has, potentially, three sets of rules to satisfy from a single incident. The deadlines may differ. The required content of the letter may differ. Whether a state official has to be told may differ.

    You do not need to memorize any of that. You need to know two things: that the number of applicable laws is driven by your people’s addresses, and that your lawyer will need that address list early. Which is a quiet argument for keeping your member records accurate and for not keeping records of people who left twenty years ago.

    What the notices generally have in common

    Details vary by state — always — but the family resemblance is strong.

    A deadline measured in days from discovery. Some states set a specific number of days; others use a reasonableness standard along the lines of the most expedient time possible and without unreasonable delay. These deadlines are not stable, either — California, which used the reasonableness language for more than twenty years, moved to a fixed 30-calendar-day notification deadline effective 1 January 2026, with notice to the Attorney General due within 15 calendar days after individuals are notified. Either way the clock starts near the beginning of the incident, usually well before you understand what happened. This is the single biggest reason to call counsel on day one rather than day ten, and to ask them what the current deadline is in each state where your people live rather than relying on anything you read a year ago.

    Required content in the notice. States commonly specify what the letter has to say: what happened, what categories of information were involved, what the organization is doing about it, what the individual can do, and who to contact with questions. Some prescribe the format and the delivery method. This is not a letter to draft yourself from a template you found online.

    Notice to a state official. Several states require that the attorney general or a similar office be told, often once the number of affected residents crosses a threshold. California, for example, requires a sample copy of the notice to be submitted to the Attorney General by any organization “required to issue a security breach notification to more than 500 California residents as a result of a single breach of the security system” (Cal. Civ. Code §§ 1798.29(e), 1798.82(f)). Other states set different thresholds, and some set none.

    Notice to the credit bureaus. Some states require the nationwide consumer reporting agencies to be notified once the affected population passes a threshold that state sets. Separately, the FTC’s breach response guidance for businesses says that “if Social Security numbers have been stolen, contact the major credit bureaus for additional information or advice,” regardless of whether a statute compels it.

    And an encryption exemption that is worth real money. This is the most actionable point in the whole area of law. Many state statutes are written around unencrypted personal information. California’s, for example, requires disclosure to a resident “whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person” — and also where encrypted information was acquired along with the encryption key or security credential (Cal. Civ. Code §§ 1798.29(a), 1798.82(a)). So encryption is not a blanket exemption anywhere, and the details differ by state. Ask your lawyer how it works in the states that apply to you.

    Encryption means the data is stored scrambled, readable only with a key. Turning on full-disk encryption on your laptops is free — it’s built into Windows and macOS — and it takes about ten minutes per machine. It will not stop a phished mailbox. But a laptop stolen from a car is one of the most common ways a small organization loses data, and encryption can be the difference between a stolen laptop and a notifiable breach. That is an extraordinary return on ten minutes, and it is a genuine, concrete reason to do it this month rather than someday.

    The first days: what to do so that you can comply

    Whether you’ll owe notice is a question for later. What you do in the first hours decides whether you’ll be able to answer it.

    Preserve everything. Do not clean up. The instinct — reset the machine, delete the bad messages, wipe it and start fresh — destroys the only record of what happened. The FTC’s guidance for businesses is direct: “Do not destroy any forensic evidence in the course of your investigation and remediation,” and “don’t turn any machines off until the forensic experts arrive.” Disconnect an affected computer from the network by unplugging the cable or switching off Wi-Fi, but leave it running and leave it alone.

    Stop the bleeding without destroying the evidence. Change passwords from a different device, sign out all active sessions, and turn on multi-factor authentication if it wasn’t already on. Preserving evidence does not mean leaving the door open.

    Write down the timeline as it happens. A plain notebook or a single document. When you first noticed something. Who reported it. What time. What you did and when. Who you called. Your lawyer will need this, your insurer will need this, and memory reconstructed three weeks later is not good enough. Start it in the first ten minutes.

    Call your lawyer before you call anyone else you’re tempted to call. Not because you’ve done something wrong, but because the deadline has probably already begun, and because counsel can often direct the investigation in a way that protects the organization. Ask specifically about a legal hold — an instruction to stop any routine deletion of records that might be relevant.

    Call your insurer the same day. Read this twice: many policies impose their own notice deadlines that are shorter than the law’s, and some require you to use their approved forensic and legal panel. Calling them late, or hiring your own investigator first, can jeopardize coverage on a policy you’ve been paying for. If you have cyber liability coverage, the hotline number is the most valuable thing in the policy.

    Report it. If money moved or fraud was attempted, report to the FBI at ic3.gov immediately. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic cases in 2025, and that process works far better inside the first 24 to 72 hours. Point affected individuals to identitytheft.gov, which walks them through recovery steps at no cost.

    Say less publicly, sooner privately. Do not speculate from the pulpit about what happened. Do tell your board chair and your leadership immediately.

    Notifying well is a trust-building act

    There’s a fear underneath all of this: that telling the congregation will destroy confidence in the church’s leadership.

    The pattern runs the other way.

    Congregations are generally forgiving about incidents. People understand that criminals exist, that a determined attack can succeed against anyone, and that ministry staff are not security professionals. What congregations do not forgive is finding out later that leadership knew and said nothing. The first is a misfortune. The second is a character question, and it is the one that ends tenures.

    A good notification is short and specific: here’s what happened, here’s what information was involved, here’s what we’ve done, here’s what we recommend you do, here’s who to call with questions, and here’s the change we’re making so it doesn’t happen again. No hedging, no passive voice, no “an incident may have occurred.” Take responsibility for the response even where you couldn’t have prevented the event.

    Handled that way, a breach notification is one of the clearer demonstrations a church can give that it treats people’s information as a trust rather than an asset. That’s not spin. It’s just what integrity looks like on a bad week.

    What to do this week

    Turn on full-disk encryption on every laptop your organization owns — BitLocker or device encryption on Windows, FileVault on Mac. Ten minutes a machine, no cost, and in many states it changes the legal character of a stolen laptop.

    Then write two phone numbers on the same card and put it where your leadership can find it: your attorney, and your insurance carrier’s claims line. Add whether you have cyber liability coverage at all — if nobody in the room knows, that’s this week’s second task, and it’s a five-minute email to your broker.

    Preparing before anything happens is far cheaper than improvising afterwards. MissionDefend’s free assessment asks straightforward questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first — including whether you’d be able to answer the questions above on the worst morning of the year.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: National Conference of State Legislatures, Security Breach Notification Laws; California Office of the Attorney General, Reporting a Data Breach; California Legislature, SB 446, Data breaches: customer notification; Federal Trade Commission, Data Breach Response: A Guide for Business; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • Keep It or Delete It? The Security Control Nobody Talks About

    Keep It or Delete It? The Security Control Nobody Talks About

    The shared drive has a folder called Old Stuff. Inside it is a folder called Old Stuff 2.

    Somewhere in there is a spreadsheet from 2011 with the name, home address, phone number, and date of birth of every child who came to vacation Bible school that summer. Those children are adults now. Most of their families moved away. Nobody has opened the file in fifteen years.

    It’s still there because deleting it never felt like anyone’s job, and because deleting things feels vaguely irresponsible — like throwing away the church’s memory.

    Here’s the thing nobody says out loud in security training, and it’s the whole point of this post:

    Data you no longer hold cannot be stolen.

    Not “is harder to steal.” Cannot be stolen. There is no attacker clever enough, no password weak enough, no misconfigured folder careless enough to expose a file that does not exist. Deletion is the only control with a perfect success rate, and it’s the one almost nobody applies.

    Deletion is a security control, not housekeeping

    Every other thing we recommend reduces the probability that something goes wrong. Multi-factor authentication makes an account much harder to break into. Backups make a ransomware attack survivable. Good habits around payment changes make fraud far less likely. All of them are worth doing, and none of them are perfect.

    Deleting data changes something different. It reduces the consequences — the size of the loss if the other controls fail.

    Think about what a breach costs a church. Almost all of it scales with how many people’s information was involved: the notification letters, the phone calls, the pastoral fallout, the trust. A compromised mailbox holding two years of correspondence is a bad afternoon. The same mailbox holding twenty years is a very different event.

    The size of your worst day is decided years in advance, by what you chose to keep.

    Why churches keep everything

    Not carelessness. Four honest reasons.

    Deleting feels like erasing people. A church’s records are its history — baptisms, marriages, funerals, membership rolls. That instinct is correct for the historical record and wrong for the operational one. Nobody is suggesting you throw away the baptismal register. We’re talking about the 2019 volunteer sign-up sheet with everyone’s cell numbers on it.

    Storage got cheap. There’s no longer a filing cabinet filling up to force the decision. Cloud storage — meaning files kept on a provider’s servers rather than a computer in your office — just quietly expands.

    Nobody owns it. Retention is nobody’s job description. It falls between the treasurer, the administrator, and the board, which means it falls on the floor.

    Fear of needing it later. This is the real one. What if we’re audited? What if there’s a dispute? That fear is legitimate, and the answer is not “keep everything forever” — it’s “find out the actual requirement, write it down, and then be free of the question.”

    A framework to start from

    What follows is general information and a starting point for a conversation, not a legal answer. Tax, employment, denominational, and state requirements all set floors, they vary by state, and they change. Confirm every line below with your accountant and your attorney before you adopt it. Two anchors are worth knowing because they come from the IRS guidance written for exempt organizations rather than from general small-business advice. IRS Publication 4221-PC tells public charities they “must keep records for federal tax purposes for as long as they may be needed to document evidence of compliance with provisions of the IRC,” notes that “generally, the statute of limitations runs three years after the date the return is due or filed, whichever is later,” and adds that if an organization has employees, “it must keep employment tax records for at least four years after filing the fourth quarter for the year.”

    Giving and donation records. Long retention. These support your tax filings and your donors’ deduction claims, and your accountant will have a firm view. Keep them — but keep them in your giving platform or accounting system, not as spreadsheets scattered across the drive.

    Member and attendance contact data. Short. This is a live directory, not an archive. If someone left the congregation in 2018, ask whether their cell number and home address need to be in an active file in 2026.

    Children’s and youth records. The most sensitive category and the one requiring the most care in both directions. Many organizations hold these far longer than the tax rules would suggest, because the window in which a claim relating to a minor can be brought is long and varies considerably from state to state — that is usually a decision driven by limitations periods and insurer expectations rather than by a statute telling you to retain the file. Do not guess here. Ask your attorney and your insurer specifically about this category.

    HR and payroll. Governed by employment and tax rules with real floors. Your payroll provider or accountant can tell you what applies. Note that the floors typically cover the tax records, not every email about the hiring process.

    Background-check results. Often among the shortest, and best held by the screening provider rather than by you. Reports from a screening company generally fall under federal consumer-reporting law, which sets its own rules for how they are used and disposed of, so this category deserves its own policy.

    Counseling and pastoral care notes. Special handling. There are confidentiality and privilege considerations that vary by state and by whether the person providing care is licensed. This is a lawyer question before it is an IT question.

    Email. The default here is genuinely wrong in most churches, which is “keep it all forever.” Ask a different question: what does your organization actually need from a mailbox that is five years old? For most staff, the honest answer is nothing.

    Photos and video. Retain the ones you use. Delete the eleven hundred near-duplicates from the 2017 mission trip. Pay particular attention to images of children, and to whether you still hold current permission to use them.

    Board minutes and governing documents. Keep permanently — the IRS guidance for public charities says to keep the application for recognition of exempt status, the determination letter, organizing documents such as articles of incorporation and bylaws, and board minutes indefinitely. These are your corporate memory and your legal backbone, and they contain almost no personal information. This is the category where “keep everything” is right.

    Where deletion quietly fails

    You delete a file. You feel better. The file is still there, in one to five other places.

    Email archives. Many organizations have archiving or journaling turned on — a system that copies every message to separate long-term storage. Deleting from the mailbox does nothing to the archive.

    Trash and recycle bins with their own timers. Deleted email goes to a trash folder. Deleted cloud files go to a drive trash. These are separate systems with separate retention periods, and most business platforms keep a further recoverable copy that only an administrator can see, for a period after that. Deleting once is rarely deleting.

    Backups. Your backup exists specifically to defeat deletion — that’s its job. A file removed today may live in backups for months. You generally shouldn’t try to surgically extract it, and you don’t need to. You do need to know your backup rotation period, so you know the honest date when the data is actually gone.

    The export on someone’s laptop. The volunteer who pulled the full membership list into a spreadsheet to do the Christmas mailing. The treasurer who downloaded giving data to work on the budget at home. These copies are invisible to every policy you write, which is why the policy has to name them: no exports to personal devices, and any working copy is deleted when the task is done.

    Third-party platforms you no longer use. The event-registration site from 2019. The old church management system you migrated away from. The mass-texting service someone trialled. Cancelling a subscription does not necessarily delete the data — many services retain it, sometimes indefinitely, unless you specifically ask. When you stop using a platform, send a written request to delete your data and keep the reply.

    And the “delete” that isn’t a delete at all. Moving a file into a folder called Archive is not deletion. It is deletion’s costume.

    The file is still on the same drive, with the same permissions, visible to the same people, included in the same backups, and exposed to exactly the same attack. Nothing has changed except that you now feel finished.

    The same is true of renaming a folder DO NOT USE, of moving old records to “that laptop in the closet,” and of unplugging a computer that still has a hard drive in it.

    Real deletion means the data is gone from the live system, gone from the trash, and on a known countdown out of backups. Anything short of that is filing.

    One hour, once a year

    A retention policy that requires a committee will never run. Here is a version that runs.

    Put one recurring reminder on the calendar. Same week every year. Call it records review. Give it sixty minutes.

    Do one category per year. Year one: email. Year two: the shared drive. Year three: old platforms and subscriptions. Trying to do all of it at once is how the whole thing gets abandoned in year one.

    Two people, not one. One person who knows where things are, one person who has authority to say delete. That pairing prevents both paralysis and mistakes.

    Write down what you did. Three lines in a document: what you reviewed, what you deleted, what you decided to keep and why. If anyone ever asks whether your organization managed its records responsibly, that log is the answer.

    Start with the easiest win. Old platforms you no longer use. Deleting an account you already stopped paying for is pure gain, and it usually takes ten minutes per service.

    The one time you stop deleting immediately

    There is an exception, and it is absolute.

    If your organization is involved in litigation, or a claim, or a government or denominational investigation — or if any of those becomes reasonably foreseeable — routine deletion stops that day, for everything that might be relevant. This is commonly called a legal hold: an instruction to preserve records that would otherwise be destroyed on schedule.

    The federal rule governing litigation in federal court is blunt. Rule 37(e) applies where “electronically stored information that should have been preserved in the anticipation or conduct of litigation is lost because a party failed to take reasonable steps to preserve it.” Note the words anticipation of. The duty can begin before anyone files anything — before you receive a letter, sometimes at the moment a serious allegation is made. State courts have their own rules, and they vary, which is another reason this is a question for your attorney rather than one to settle from a blog post.

    Practically, that means two things. Deleting on a published schedule, before any of this arises, is ordinary responsible practice. Deleting after it arises is a separate and much more serious problem, and the appearance of it is nearly as damaging as the fact.

    So: get your attorney’s guidance on when a hold starts, know how to pause your routine, and if there is any question at all about whether something is in dispute — stop, and ask before you delete.

    What to do this week

    Open the list of software your organization pays for, or used to. Pick one service you no longer use, log in, and delete your data — or email their support address asking them to delete it and save the reply.

    Then put one recurring calendar reminder in place, once a year, sixty minutes, called records review. That reminder is the entire policy. Everything else is detail you can add later.

    Twenty minutes, and you’ve turned “we should really deal with that someday” into something with a date on it.

    MissionDefend’s free assessment works through the same ground in plain English — where your organization’s information actually lives, who can reach it, and what’s still being kept for no reason — and hands you a baseline score with a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Internal Revenue Service, Publication 4221-PC, Compliance Guide for 501(c)(3) Public Charities; Internal Revenue Service, Recordkeeping requirements for exempt organizations; Legal Information Institute, Cornell Law School, Federal Rule of Civil Procedure 37(e).

  • Background Checks: Who Holds Them, For How Long, and How to Destroy Them

    Background Checks: Who Holds Them, For How Long, and How to Destroy Them

    There is a drawer in most church offices that nobody thinks about.

    It holds background-check results. Every volunteer who has ever worked with children, going back as far as the church has been screening people. Some of them are printouts stapled at the corner. Some are in a folder on the shared drive called Screening. Most of them, if we’re honest, are still sitting in the office administrator’s email as PDF attachments, because that’s how the screening company delivered them and nobody ever moved them anywhere else.

    You did the screening because you take child safety seriously. That was the right call, and your insurer and your denomination probably required it.

    But the screening created something new: a small, concentrated archive of the most sensitive personal information your organization will ever touch, held by an office that was never set up to hold it.

    This post is about what to do with that archive.

    What’s actually inside one of those reports

    A background check is not a yes-or-no answer. It’s a document, and the document is dense.

    Depending on the provider and the level of check, it typically contains the person’s full legal name and any former names, date of birth, current and previous home addresses, and often all or part of a Social Security number — because that number is how the provider matches records to the right human being. Then it contains the results: county and state criminal records, sex offender registry checks, sometimes driving records, sometimes credit information.

    That combination is unusual. Plenty of organizations hold names and addresses. Far fewer hold a name plus a date of birth plus a Social Security number plus a home address, all in one file, for dozens of people at once.

    That specific combination is everything someone needs to open credit in another person’s name. It is, in practical terms, the highest-value data a small church holds — more valuable to a thief than your giving records.

    And there’s a second harm on top of the financial one. These files may contain criminal history for volunteers your church screened, considered, and welcomed anyway. A leak doesn’t just expose an identity. It exposes something a person told you in confidence, about the hardest part of their life, in order to serve. Losing that is a pastoral failure as much as a technical one.

    Where these files actually end up

    None of the following is negligence. Every one of them is what happens when a small office handles a task it was given without being given a system.

    In an inbox, forever. The screening company emails a PDF — a PDF is just a document file, and one that keeps its formatting and can be opened by anyone, with no protection unless someone deliberately adds it. It arrives, gets read, gets acted on, and stays in the mailbox. Five years later it’s still searchable by typing a volunteer’s last name, and if that mailbox is ever compromised, so is every report in it.

    In a shared drive folder open to everyone. Cloud drives default to convenient, not restrictive. A folder created by one person is very often visible to every staff account, and sometimes to every volunteer who was ever added to the team drive.

    In a filing cabinet in an unlocked office. The cabinet may lock. The question is whether it is locked at 4pm on a Thursday when the building is open for choir practice and a dozen people are walking past the door.

    For people who left a decade ago. This is the most common one. Nobody ever decided to keep the file of a nursery volunteer who moved away in 2014. Nobody decided to delete it either. Absent a decision, records simply accumulate.

    On a former administrator’s laptop. Someone downloaded the reports to work from home during a busy screening season. That laptop left with them.

    The rule that fixes most of this

    Here it is, and it’s simpler than any policy document:

    Keep the decision. Don’t keep the report.

    Your organization needs to be able to prove that a volunteer was screened, when, by whom, and that they were approved. That’s a single line in a roster: Name — screened 14 March 2026 — provider — cleared — approved by [name].

    What your organization almost never needs is the underlying report sitting in your building. The screening company already has it. That’s their business, they’re built for it, and they carry insurance for it.

    So the default should be: the provider holds the report; you hold the record of the decision.

    Most screening platforms let you view results in their portal rather than emailing them out, and many will let you turn off attachment delivery entirely. Ask your provider two questions: Can results stay in your system instead of being emailed to us? and How long do you retain them, and can we retrieve them later if we need to?

    If the answer to the first is yes, you have just removed the entire problem from your building.

    Where you genuinely must keep something — because your insurer, your denomination, or your state’s volunteer rules require a copy — keep the smallest version that satisfies the requirement, and store it in one place, not four.

    What the law expects, in general terms

    Some real caution here: this is the shape of the rules, not advice about your situation. Requirements differ meaningfully by state, by whether you use a screening company, by the type of work the volunteer does, and by whether the person is an employee or a volunteer. Your attorney and your insurance carrier should confirm your policy before you adopt it.

    With that said, three things are worth knowing.

    Reports from a screening company are usually “consumer reports.” When you buy a background check from a third-party screening company, that report generally falls under the Fair Credit Reporting Act (FCRA) — the federal law governing how consumer reporting information is obtained, used, and disposed of. The FTC and EEOC’s joint guidance for employers walks through the obligations that come with it, including giving the person a clear written notice and getting written permission before you run the check, and giving them a copy of the report and a statement of their rights before you turn them down because of it.

    There is a federal rule specifically about throwing these away. The FTC’s Disposal Rule (16 CFR Part 682) requires anyone who maintains or possesses consumer information for a business purpose to dispose of it “by taking reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal.” The FTC’s own business guidance states plainly that “any business or individual who uses a consumer report for a business purpose is subject to the requirements of the Disposal Rule,” and names employers among them. Its examples of reasonable measures: “burn, pulverize, or shred papers,” and “destroy or erase electronic files or media” so the information “cannot be read or reconstructed.”

    Retention floors exist and they’re shorter than you’d guess. The FTC/EEOC guidance points to the EEOC’s requirement that personnel and employment records be “preserved for one year after the records were made, or after a personnel action was taken, whichever comes later.” That is an employment rule, and whether it reaches your organization at all depends on your size, on whether the person is an employee or a volunteer, and on how the exemptions for religious employers apply to you. Other floors may apply too — from your state, your denomination, or your insurer. Ask. But notice the direction of the surprise: the legal floor is often low, and the reason churches keep these files for fifteen years is habit, not law.

    Building a retention rule you’ll actually follow

    A retention policy that lives in a binder is not a control. Keep it to five sentences someone can act on.

    Name two people. Access to screening results is limited to two named individuals — typically the safeguarding lead and one other. Not “the office.” Not “staff.” Two people, by name, written down. Everyone else sees the roster line, not the report.

    Pick one location. One folder, one cabinet, one portal. Multiple copies in multiple places is the actual failure mode, because you can clean up the one you remember and miss the three you don’t.

    Write the period down. Something like: background-check results are retained for [X] years after the volunteer’s service ends, then destroyed, with X confirmed by your attorney and insurer. The number matters less than the fact that a number exists.

    Put it on the calendar. A recurring annual reminder — “review screening files” — is what turns a policy into a practice. Without it, nothing is ever destroyed.

    Write down what you’ll keep forever. Usually just the roster: who was screened, when, and that they were cleared. That’s the record that protects the church years later, and it contains no Social Security numbers at all.

    Destroying them properly

    Destruction is where good intentions quietly fail, because “delete” means less than people think.

    On paper: cross-cut shred, or use a bonded destruction service that gives you a certificate. Do not put them in the recycling bin. Do not put them in the dumpster behind the fellowship hall.

    In email: deleting the message is not enough. Empty the trash or deleted-items folder too, and remember that most mail systems keep a further recoverable copy for a period after that. Check whether your provider offers a permanent-delete option, and if attachments were forwarded to anyone, delete them from those mailboxes as well.

    On a shared drive: delete the file, then empty the drive’s own trash, which usually runs on a separate timer from your email trash. Then check whether anyone downloaded a copy.

    In backups: this is the one everyone forgets. Your backup exists precisely to make deletion reversible. A file removed today may sit in backups for months. You usually can’t and shouldn’t surgically remove it, and that’s fine — but you should know the rotation period, and note that the file isn’t fully gone until that period has passed.

    On old hardware: a retiring laptop or copier can hold every report ever printed. Have drives wiped or destroyed before anything leaves the building.

    What to do this week

    Search your own mailbox for the name of your screening provider, and see how many reports come back. That number, whatever it is, is the honest starting point — and finding it takes about five minutes.

    Then do one thing: call the provider and ask whether they can stop emailing results and let you view them in their portal instead. That single change stops the pile from growing while you decide what to do about the files you already have.

    Sensitive records are one of several places churches carry more risk than they realise. MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts — including where sensitive records like these actually live — and returns a baseline score with a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission and Equal Employment Opportunity Commission, Background Checks: What Employers Need to Know; Federal Trade Commission, Disposing of Consumer Report Information? Rule Tells How; Electronic Code of Federal Regulations, 16 CFR § 682.3 — Proper disposal of consumer information.

  • The Most Sensitive File in the Building

    The Most Sensitive File in the Building

    A pastor sits down after a Thursday afternoon conversation and writes half a page of notes. A marriage in trouble. A relapse. A name and a date and enough detail to remember what to follow up on next month.

    The notes go into a Word document on the office laptop, in a folder called Care. The laptop is the one the whole staff borrows when theirs is charging. The folder syncs to the shared drive, because everything on that laptop syncs to the shared drive — that’s how it was set up years ago, and it was set up that way so nothing would ever be lost.

    Every person on staff can open that folder. Not one of them ever has. That isn’t a security control; it’s good manners.

    Elsewhere in the same building: benevolence applications with bank details and eviction notices in a cabinet that doesn’t lock, a text thread on a personal phone that contains a full disclosure of abuse, and a notes field in the church management software where somebody typed “husband’s drinking again — do not mention to the Wilsons” three years ago, not realizing that eleven volunteers can see it.

    This is the most sensitive information any church holds, and it is almost always the least protected.

    Confidentiality and security are two different things

    This distinction is worth slowing down for, because the two are constantly confused.

    Clergy confidentiality — often discussed alongside the clergy-penitent privilege, a legal rule about what a minister can be compelled to testify to in court — is a legal and ethical concept. It’s about who may lawfully demand the information, and what a minister is obliged to do with it. Its scope varies significantly by state, and denominations layer their own ordination vows and disciplinary standards on top. Some states affirm the privilege broadly, some limit it to confessional communications, and the Children’s Bureau’s fifty-state summary notes that in some states it is denied altogether.

    Data security is about who can physically or technically reach the file. Passwords, permissions, locks, encryption.

    Here is the load-bearing sentence: a note that is privileged in principle is still readable by anyone with the password. Privilege governs a courtroom. It does nothing whatsoever against a compromised email account, a laptop left in a car, or a volunteer clicking into a folder they shouldn’t have been able to open.

    A related confusion is worth clearing up. Churches often assume health-privacy law covers them. Generally it does not — the federal rule applies to health plans, health care clearinghouses, and health care providers who transmit certain information electronically in connection with standard transactions. A congregation offering pastoral care isn’t ordinarily any of those. There may be exceptions if your ministry operates a counseling center, employs licensed clinicians, or bills insurance, and that’s a question for your attorney. But do not assume a federal law is protecting these records. Usually nothing is except your own practices.

    And one thing that overrides all of it: mandatory reporting obligations exist, they vary, and in defined circumstances they take precedence over confidentiality. According to the Children’s Bureau’s summary of state statutes, members of the clergy are named as mandated reporters in 29 states and Guam, and seven jurisdictions — New Hampshire, North Carolina, Oklahoma, Rhode Island, Texas, West Virginia, and Guam — disallow the clergy-penitent privilege as grounds for failing to report suspected child abuse or neglect. Four states — Indiana, New Jersey, North Carolina, and Wyoming — require all persons to report regardless of profession. That summary is current through May 2023 and these laws change. Know your own state’s rule cold, in writing, before you need it. Ask a lawyer. This article is not legal advice.

    Decide what gets written down at all

    The most effective control here isn’t technical. It’s editorial.

    Before you write anything, ask: what do I actually need to remember, and what would harm this person if it were read by someone else? Those two answers overlap far less than people assume.

    A workable standard for care notes in a congregational setting:

    Write enough to follow up. Date, who you met with, that a conversation happened, and what you committed to do. “Met with R. Follow up in two weeks. Referred to counseling resource list.”

    Leave out the detail that isn’t yours to hold. The specifics of a disclosure, third parties’ names, diagnoses, financial particulars, anything about someone’s spouse or children who were not in the room. If you don’t need it to be a good pastor next month, it doesn’t need to exist on paper.

    Never write speculation, judgment, or diagnosis. Not because someone might sue, though they might, but because you’re recording a guess about a human being that will outlive your memory of how uncertain you were.

    Assume it will be read. By a successor, by a board in a conflict, by a court under subpoena, by an attacker in a breach. Write the note that you would be content to have read aloud.

    This is not an argument for keeping no records. Continuity of care matters, and a pastor who remembers nothing serves people badly. It’s an argument for writing the minimum that does the job.

    Where these files should actually live

    Out of the general shared drive. This is the single highest-value change most churches can make in an afternoon. The default setup at a small organization is one shared drive, open to all staff, because that was simplest to configure. Care notes and benevolence files need to come out of it into a separate location with its own permissions.

    Access granted to named people, not to “staff.” There is a real difference between a folder shared with the staff group and a folder shared with Pastor Miller and Pastor Ruiz. The first automatically includes every future hire, every intern, and the office volunteer who was added to the group last spring. The second doesn’t. Name the individuals.

    Paper goes in a locking cabinet, and the key is controlled. Benevolence applications in particular — they routinely contain bank account numbers, Social Security numbers, pay stubs, and eviction notices, which is a more complete identity-theft package than most churches hold anywhere else.

    Set a retention limit and honor it. Decide how long care notes and benevolence files are kept, write it down, and destroy them on schedule. Records you no longer hold cannot be exposed, subpoenaed, or misread by a successor. What the right period is depends on your state, your denomination’s polity, your insurer, and whether any licensed counseling is involved — ask your attorney for the number, then follow it.

    Multi-factor authentication on the accounts that can reach any of this. MFA is the extra code or tap after the password. It’s free on Microsoft 365 and Google Workspace, and Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. If a folder is worth restricting, the account that can open it is worth protecting.

    Email, texting, and the notes field nobody thinks about

    Email is a filing cabinet you don’t control. A message about a member’s situation is copied into the sender’s sent folder, the recipient’s inbox, both mailboxes’ backups, and the provider’s servers. It stays there for years. If either account is ever compromised — the most common single security incident at any organization — the attacker gets not just the mailbox but the searchable history of everything the church knows about its people.

    If you must send something by email, keep the substance out of the subject line. Subject lines appear in notification previews on lock screens, on shared reception monitors, in mobile summaries, and in any forwarded thread. “Re: Thursday” is a fine subject line. “Re: Dana’s rehab intake” is a broadcast.

    Better: send “Can we talk about a pastoral matter today?” and have the conversation by voice.

    Texting is worse, and it’s what people actually use. A pastoral text thread sits on a personal phone with no organizational control at all. It appears in lock-screen previews. It’s visible to anyone who picks up the phone, including a spouse or a child. It backs up to a personal cloud account. And when that pastor leaves the church, the entire history leaves with them, on their device, permanently. Text to arrange a meeting. Don’t text the meeting.

    The church management software notes field is far more visible than people think. Almost every ChMS — church management software, the system that holds your directory, attendance, and giving — has a general notes or comments field on each person’s record. Staff type sensitive things into it because it’s convenient and it feels private.

    It usually isn’t. Depending on how your permissions are configured, that field may be visible to every staff member, every group leader, every volunteer with a login, and anyone who can run an export. Go look today: log in as a volunteer-level user, or ask one to show you their screen, and see exactly what a group leader can read on a member’s record. Most churches are surprised. Then either lock the field down properly or stop using it for anything but logistics.

    Two situations to plan for now

    When a staff member leaves. This is the moment the whole problem becomes visible. Their church account gets disabled — but the notes in their personal notebook go home in a box. The care history in their text messages leaves on their phone. The documents in their personal Dropbox stay in their personal Dropbox.

    Handle it at the front end rather than the back: make it clear from the first week of employment that ministry records belong to the ministry and live in ministry systems. Then, at departure, walk through it explicitly — accounts disabled, church files returned or transferred to the named successor, personal-device copies deleted, paper handed over. Have the conversation warmly and have it anyway, including when someone leaves on the best possible terms.

    When a device is lost. A laptop in a stolen car, a phone left in an airport. If care notes were on it, the question is whether anyone can read them.

    Two settings make the answer no, and both are free and already built in. Full-disk encryption — BitLocker on Windows, FileVault on Mac — scrambles everything on the drive so it’s unreadable without the login. On phones and tablets it’s on by default as long as you have a passcode. And remote wipe, which lets an administrator erase a device that’s gone. Turn both on across every device that touches ministry records, today, before you need them.

    If a device is lost, change the passwords for every account that was signed in on it, sign out all active sessions, and tell someone immediately. If information about people was exposed, notification requirements exist in every state and vary considerably — that’s a call to your attorney, promptly.

    What to do this week

    Open your shared drive and look at who can see the folder containing care notes, benevolence applications, or anything similar. If the answer is “everyone on staff,” move that folder somewhere with permissions granted to two or three named people. Fifteen minutes.

    Then log in to your church management software as a volunteer-level user and read what they can see on a member’s record. If the notes field is exposed, you’ve just found this week’s second job.

    MissionDefend’s free assessment asks straightforward questions about how your organization handles member data, accounts, email, and donations — no jargon — and returns a baseline score with the highest-value fixes ranked in order.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: U.S. Department of Health and Human Services, Children’s Bureau, Mandatory Reporting of Child Abuse and Neglect: State Statutes; U.S. Department of Health and Human Services, Covered Entities and Business Associates; Microsoft, mandatory multifactor authentication guidance; National Conference of State Legislatures, Security Breach Notification Laws.

  • What Do You Actually Have? A One-Afternoon Data Inventory

    What Do You Actually Have? A One-Afternoon Data Inventory

    Someone in the office asks a simple question: where do we keep the allergy list for the kids?

    Four answers come back. It’s in the check-in system. It’s also on a printed sheet in the nursery binder. Sarah keeps a copy on her phone because the tablet is slow on Sunday mornings. And there’s a spreadsheet somebody emailed around before the fall kickoff, which is still sitting in maybe nine inboxes.

    All four answers are true. That’s the problem.

    This isn’t a story about carelessness. It’s what happens when a small organization runs on goodwill and improvisation for a decade. Nobody decided to keep four copies of children’s medical information. It accumulated, the way things accumulate in a building that’s been used by a lot of people for a long time.

    You cannot protect what nobody has written down. Every other security decision you’ll make — who gets multi-factor authentication first, what to back up, what to shred, what to tell people if something goes wrong — depends on knowing what you’re holding and where it lives. That knowledge almost never exists in one place. Building it takes an afternoon.

    Why this is the first job, not the fifth

    Most security advice starts with a control: turn on this setting, buy this tool, write this policy. Those are all reasonable, and they’re all guesses until you know what you have.

    The Federal Trade Commission’s guide for businesses puts inventory first, before locks and disposal, in a single sentence: know what personal information you have in your files and on your computers. Not because it’s exciting, but because everything downstream is unanswerable without it.

    Consider what you can’t decide today. Is your backup adequate? Depends what needs backing up. Should the giving system have stricter access than the calendar? Obviously — but who has access to the giving system right now? If a laptop went missing tonight, what would be on it? If you had to notify people that their information was exposed, which people, and how would you reach them?

    Every one of those is a lookup against a list you don’t have yet.

    The four questions, and a table to hold them

    For each thing you find, you’re answering four questions. That’s the whole method.

    What is it? In plain words. Not “member records” — names, home addresses, phone numbers, birthdays, and marital status for about 340 households. Be specific enough that a stranger reading the line understands the sensitivity.

    Who can reach it? Not who should. Who actually can, today, if they tried. This includes anyone who knows a shared password, anyone whose account was never turned off, and the person who has a key to the cabinet.

    Where does the copy live? Plural, almost always. The system of record, plus the export somebody made, plus the printout, plus the backup, plus the attachment in the email thread.

    Do we still need it? The most useful question on the list, and the one that shrinks the problem fastest. Data you deleted cannot be stolen.

    Put the answers in a table — one row per thing. A single shared document, or a printed sheet on a clipboard. Either works.

    What it isWhere the copies liveWho can reach itSensitivityStill need it?
    Member directory — names, addresses, phones, birthdays, ~340 householdsChMS; export on office PC desktop; printed pictorial directory (2021)3 staff logins; 1 shared “office” login; anyone with the printed copyHighYes — but delete the desktop export
    Children’s check-in, allergies, emergency contactsCheck-in system; nursery binder; volunteer’s phone photo; emailed spreadsheet6 volunteers via shared tablet login; ~9 email recipientsVery highYes — one copy only
    Background check results, 2016–presentVendor portal; paper files, unlocked cabinetVendor login shared by 2 people; anyone in the officeVery highCheck retention rule with counsel
    Giving and pledge recordsGiving platform; QuickBooks; annual statement PDFs on shared driveTreasurer, bookkeeper, pastor; shared drive is open to all staffHighYes — restrict the drive folder
    Old laptop, closetUnknownAnyone who opens the closetUnknownNo — wipe and dispose properly

    The sensitivity column is a judgment call, and a coarse one is fine. High, medium, low. What you’re really flagging is: how bad would it be if this ended up somewhere public, or in the hands of someone who wanted to harm one of these people? A birthday list is not the same as a benevolence file.

    Now go find the rows.

    Walk the building

    Do this part physically. Take a legal pad and actually open the doors.

    The office. Filing cabinets — including the one nobody has a key for, which you should note as an open item rather than skip. Look for personnel files, background check results, old giving envelopes, offering count sheets, contribution statements, and applications from volunteers who came and went years ago.

    The children’s and youth area. Check-in records, allergy and medical information, emergency contacts, permission slips, incident reports. This is usually the most sensitive paper in the building and the least locked.

    The pastor’s study and the counseling room. Care notes, benevolence applications, correspondence. Handle this category with particular seriousness — it deserves its own conversation, and we’ll cover it separately.

    The closet, the storage room, the attic over the fellowship hall. Old computers. Old phones. A retired copier — the FTC’s guidance for businesses is blunt about this: the hard drive in a digital copier stores data about the documents it copies, prints, scans, faxes, or emails, and deleting or reformatting doesn’t actually remove it. Boxes of paper somebody meant to sort.

    The counters and desks. The sticky note with the Wi-Fi password is a minor issue. The sticky note with the login for the giving platform is not.

    Walk the accounts

    Now sit down and list the online services. This is harder, because there’s no door to open. Start from three places: the bank statement (what are you paying for?), the office computer’s saved passwords or bookmarks, and the memory of whoever has been around longest.

    Expect to find: the church management software, the giving or donation platform, the payroll provider, the accounting system, the email and file storage (Microsoft 365 or Google Workspace), the website and its hosting, the domain registrar, the email newsletter tool, the event registration tool, the background check vendor, the livestream and video accounts, the social media pages, and the survey tool somebody used once for a stewardship campaign.

    For each one, the question that matters most is the second one: who can reach it? Log in and look at the user list. Do not rely on memory.

    And then the category that catches everyone: the personal accounts holding church data. The volunteer who built the directory in her own Google Sheets. The worship leader whose personal Dropbox has every service recording. The former treasurer’s home computer, where the QuickBooks file lived. These are not violations of trust — they’re what happens when someone volunteers to help and uses the tools they already have. But that data is outside anything you control, and it walks out the door when they do.

    What you will find, because everyone finds it

    Three discoveries happen in nearly every inventory. Name them in advance so nobody feels caught out.

    The shared login. One username and password for the giving platform, or the check-in tablet, or the Facebook page, used by five people, three of whom no longer serve. It exists because it was easier, and because individual accounts sometimes cost money per seat. The cost of it is that you can never tell who did what, and you can never remove one person without disrupting everyone.

    The departed volunteer who still has access. The youth intern from two summers ago whose account was never disabled. The former board member still in the shared drive. Offboarding is the single most commonly skipped step in small organizations, because there’s rarely a formal offboarding at all — people just stop coming.

    The spreadsheet that was emailed around. Somebody exported the directory to help with a mailing, attached it to a message, and sent it to eleven people. Every one of those copies is now permanent, sitting in eleven mailboxes, four of which are personal accounts with no multi-factor authentication — MFA, the extra code or tap after the password. If any one of those accounts is ever compromised, your directory goes with it.

    None of these are failures of character. They’re the predictable result of a small staff doing a large job. Write them down without commentary, and fix them in order.

    Turning the list into decisions

    The inventory is only worth the afternoon if it changes something. Three immediate moves come almost free.

    Delete. Go down the “still need it” column and act on every no. Old exports, duplicate spreadsheets, applications from people who never served, printed directories from four years ago. Paper goes in a shredder, not a recycling bin. Devices need to be properly wiped, not just deleted from — get help with that if you’re unsure.

    Reduce copies. For anything marked very high, drive it toward a single authoritative copy with controlled access. The nursery binder and the phone photo and the emailed spreadsheet all go away; the check-in system stays.

    Fix the access list. For the three or four most sensitive systems, remove everyone who shouldn’t be there, and put individual logins in place of shared ones where you can.

    Two things to note but not solve today. Records retention — how long you’re required to keep giving records, personnel files, and background checks — has real legal and tax dimensions, and the answer differs by state and by what kind of organization you are. And if information about people is ever exposed, notification requirements exist in all fifty states, the District of Columbia, and several territories, and they vary considerably in who they cover and what they require. Both of those are questions for your attorney, with your inventory in hand. The inventory is what makes that a thirty-minute conversation instead of a three-hour one.

    What to do this week

    Block ninety minutes. Take a legal pad and walk the building — office, children’s area, closets, storage. Write down every place you find information about a person, and note who can reach it. Don’t fix anything yet; just list it.

    Then open the two systems that hold your most sensitive data — usually the check-in system and the giving platform — and look at the user list. Remove anyone who has left.

    That’s it for week one. You’ll have more of a security program than most organizations twice your size.

    Once you know what you hold, the next question is how well it is protected. MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first. An inventory like this makes those answers much easier to give.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, Protecting Personal Information: A Guide for Business; Federal Trade Commission, Digital Copier Data Security: A Guide for Businesses; National Conference of State Legislatures, Security Breach Notification Laws.

  • The Scam Your Congregation Won’t Tell You About

    The Scam Your Congregation Won’t Tell You About

    Marian has not missed a Sunday in nineteen years. She runs the prayer chain. She was married forty-one years and widowed four years ago.

    In February she stopped putting anything in the offering plate. In April she took out a home equity loan. In June she asked the treasurer, oddly, whether wire transfers to Hong Kong were normal.

    Nobody put it together, because nobody was looking, and because Marian had told no one about the man she’d spoken with every day since January — a widowed contractor working overseas, a believer, someone she prayed with most nights before bed. By August she had sent him everything she had, and she still didn’t believe he was a fraud when her son sat her down with the evidence.

    Some version of this is happening in your congregation right now, and the reason you haven’t heard about it is the most important fact in this article.

    What we’re actually talking about

    The FBI calls it confidence fraudconfidence/romance fraud in its annual crime report. Its definition covers anyone who believes they are in a relationship — romantic, friendly, or familial — and is tricked into sending money or information. Romance is only one flavor. A friendship works, and so does a fake grandchild in trouble.

    In 2025 the FBI’s Internet Crime Complaint Center logged 23,159 confidence and romance fraud complaints, with reported losses of $929,287,469 — of which 10,188 complaints and $584,032,745 came from people aged 60 and over. Those figures understate the problem badly, because most victims never report. This is the crime people are most ashamed of, and shame keeps it off the ledger.

    You may also have heard the phrase “pig butchering” — the operators’ own term for fattening a target with attention and small wins before taking everything. It’s an ugly thing to say about a member of your church; the honest description is confidence fraud with an investment ending.

    How it actually works

    The shape is remarkably consistent, and the shape is what you can hand your congregation.

    It starts sideways. Often with a text to the wrong number — “Hi David, are we still on for lunch Thursday?” — then a polite reply, a warm apology, and a conversation. The FTC lists “‘wrong number’ texts that aren’t” among the top reported text scams and describes what follows exactly: “These scammers strike up a fake friendship, often with romantic undertones.” It also begins in dating apps, Facebook groups, and comment threads under Christian pages.

    Money is not mentioned for a long time. Weeks, frequently months. This is what everyone gets wrong: they picture a stranger asking for money on day three. What happens instead is a hundred days of good-morning texts and how did the appointment go and remembering the anniversary of a spouse’s death. By the time money appears there is a real relationship, real on one side, and real relationships are where guards are down by design.

    There’s always a reason you can never meet. Working overseas, on an oil rig, in the military. Video calls don’t work, or are brief and strange, or lately synthetic — the FBI notes that scammers promise to meet and then cancel, and increasingly use deepfakes.

    The ending has two forms. Either a crisis — a medical emergency, a customs fee, a frozen account — or, increasingly, an investment. He’s done well trading cryptocurrency and offers to teach her. She puts a small amount into a platform that looks entirely professional, watches it grow, and withdraws a little successfully — the moment the trap closes. Then she puts in more, and when she tries to withdraw there are taxes to pay first. The FBI is blunt: “This is a trap.”

    Faith is used as the lever, deliberately

    This is the part that will make you angry.

    Scripts written for churchgoing targets include church. He was raised in the faith. He’s been looking for a congregation since he moved. He asks what she’s been reading and sends a verse in the morning. He prays with her on the phone — at length, and well, because someone in the operation has studied the vocabulary.

    It works for a specific reason: in a faith community, shared belief is a legitimate accelerant for trust. That is not a flaw in your people — it’s why a church can care for its members in a way a subdivision cannot. The fraud borrows that instinct, which is why the usual advice, don’t trust strangers online, lands wrong. He isn’t a stranger. He’s a brother in Christ who calls every night.

    Why they defend him

    By the time anyone notices, it isn’t about money. She is not defending an investment. She is defending a relationship — and the person telling her it isn’t real is telling her that the best thing in her life since her husband died was a fiction built by strangers. Admitting that means accepting, all at once, that the money is gone, that eight months were invented, that everyone will find out, and that she participated. The mind does not take all of that on a Tuesday afternoon in a kitchen. It resists, and resistance looks like stubbornness from outside.

    The scammer prepared the ground months ago. Operators inoculate against interference early: your children won’t understand. Your church will judge us. People will say I’m after your money. So the son arrives with his printouts having already been predicted — which makes the scammer look right and the son look like the thing foretold.

    Confrontation therefore backfires. Pressing harder, producing more evidence, gathering the family: all of it deepens the commitment, because every concession costs more than the last. What helps is slower — staying in relationship, asking questions rather than issuing verdicts, and being there when the belief cracks. It usually cracks on its own, when a withdrawal fails or the demands turn cold.

    One more fact belongs in your teaching. The person typing those messages is very often not a criminal in any sense your church would recognize. The FBI has warned that fake job advertisements lure people to Southeast Asia, where they are “held against their will, intimidated, and forced to commit international cryptocurrency investment fraud schemes” — passports taken, violence threatened, debts manufactured and raised each time they’re moved between compounds. The man praying with Marian at eleven at night may be someone who answered an ad for a customer service job and is beaten if he misses his numbers. That reduces the harm to Marian by nothing, but it moves the anger away from a caricature and toward an industry destroying people at both ends.

    What a leader can actually do

    Talk about it from the front, before it happens to anyone. Five minutes on a Sunday, and the highest-value thing on this page. Say plainly that this happens to church people, that it is not a stupidity problem, and that anyone caught in it can say so without being ashamed. Silence is the environment the fraud requires.

    Name the patterns out loud. Vague warnings don’t help. These do:

    • Someone you have never met in person who talks about faith early and often.
    • A “wrong number” text that turns into a friendship.
    • Moving quickly from a dating app or Facebook to WhatsApp, Telegram, or private texting.
    • Video calls that never quite happen.
    • Any investment introduced by a romantic interest — no exceptions, however well it’s going.
    • Being told your family and your church will not understand.
    • Any request to receive money and pass it along — that is money laundering.

    Give your people one rule to hold onto: before you send money to someone you have never met, tell one other human being. Not for permission — just say it out loud. Isolation is the load-bearing wall of the scheme.

    Tell your finance volunteers what to watch for. A long-standing giver who stops abruptly. Unusual questions about wire transfers, cryptocurrency, or gift cards. A member who suddenly needs benevolence help and won’t say why. None is proof; each is worth a gentle conversation.

    Build your older-adult ministry with this in mind. In 2025 the FBI logged 201,266 complaints from people aged 60 and over, totalling $7.748 billion — complaints up 37% and losses up 59% in a single year, average loss $38,500. Loneliness is the underlying vulnerability, and it is the one thing a church is unusually equipped to address.

    When someone tells you

    Assume it took weeks to work up to it, and that they arrived braced for your disappointment.

    Believe them and don’t flinch. The first thirty seconds set everything. Thank you for telling me. You’re not the first person I’ve talked to about this.

    Never ask how they could have fallen for it — not once, not as a joke, not months later. That question closes the door for good. And don’t demand they accept it’s fake all at once. Ask questions instead: has he ever been able to video call? What happened when you tried to take money out? Let the contradictions do their own work.

    Move to practical steps quickly, because action helps a person in shock more than reassurance does. Stop sending money today. Report it at ic3.gov with dates, amounts, account numbers, wallet addresses, and transaction IDs. Call the bank or platform that sent it and ask about a recall. If personal information was shared, go to identitytheft.gov. Keep everything — the messages, the photos, the app.

    Be honest that recovery is rare. Where money is still in transit the FBI’s Recovery Asset Team can act — 3,574 domestic incidents and $507,042,623 frozen in 2025 — but that depends on speed, and this is usually found months late.

    Then warn them about the second scam, by name. Victims get re-targeted, often within weeks, by “recovery services” offering to retrieve the stolen funds for an upfront fee. The FBI has repeatedly warned about fictitious law firms contacting cryptocurrency fraud victims with exactly this offer, and about criminals impersonating the IC3 itself. Say it plainly: nobody who contacts you first can get your money back.

    Then the part that is actually your work. When you sit with someone in the weeks afterward, you’ll find the money — even a devastating amount of it — is not what they cry about. They cry because he’s gone. Because the person who texted good morning every day for eleven months, who prayed with them, who knew their late husband’s birthday, did not exist.

    That is a bereavement and deserves to be treated as one. They lost a relationship and are expected to feel foolish for having had it, which is exactly why so many never tell anyone.

    Your job is not to explain how the fraud worked; they’ll learn that. Your job is to make sure they aren’t alone in the kitchen, and to say more than once that the love they gave was real even though the person receiving it wasn’t. Both are true. Only one of them is a crime.

    What to do this week

    Say it from the front on Sunday. Two minutes: This is happening to church people. It starts as a friendship, often with someone who talks about faith. It takes months. If you’re in it, come talk to me and nobody will make you feel foolish.

    Then four lines in the newsletter: never send money to someone you have never met; never invest on the advice of a romantic interest; tell one other person before you send anything; report it at ic3.gov.

    Two minutes on a Sunday and one call to your communications volunteer, and you’ve removed the shame that keeps this crime invisible.

    MissionDefend’s free assessment covers the organization’s own posture — email, donations, member data, and accounts — and returns a baseline score with a ranked list of what to fix first. A good companion to the work of protecting the people in the pews.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report; FBI, Cryptocurrency Investment Fraud; FBI Internet Crime Complaint Center, The FBI Warns of False Job Advertisements Linked to Labor Trafficking at Scam Compounds; FBI Internet Crime Complaint Center, Fictitious Law Firms Targeting Cryptocurrency Scam Victims Combine Multiple Exploitation Tactics While Offering to Recover Funds; FBI Internet Crime Complaint Center, FBI Warns of Scammers Impersonating the IC3; Federal Trade Commission, Top text scams of 2024.

  • Protecting the Livestream, the Funeral, and the Small Group Call

    Protecting the Livestream, the Funeral, and the Small Group Call

    The funeral is on a Saturday morning. Forty people in the sanctuary and sixty more watching from Ohio, Arizona, and a hospital room in Nashville, because that’s who the livestream is for — the family who couldn’t travel.

    Eight minutes in, during the eulogy, someone joins the call and shares their screen. What appears is pornographic. Then a second person joins, and there’s shouting over the audio and slurs in the chat, and the volunteer at the laptop at the back is clicking frantically through a settings menu he has never opened while a woman in the front row watches her mother’s funeral come apart.

    It lasts ninety seconds. People will remember it for thirty years.

    This is the article about making sure that doesn’t happen at your church, written so the person running the laptop can follow it. But start with the right frame: this is a pastoral emergency that happens to have a technical cause. The technical part is genuinely easy. The part where you sit with the family afterward is not, and it’s the part most guidance leaves out.

    The root cause is the permanent public room

    Nearly every incident traces back to one habit: a meeting room that is always the same address, always open, and posted where anyone can find it.

    It’s a reasonable habit. You want people to join without friction, and grandparents shouldn’t need a new link every week. So the link goes on the website, in the bulletin PDF, on the Facebook page, and into an email list that gets forwarded — and stays there, unchanged, for years.

    Which means it can be found. There are people who do nothing but collect these links from public pages and forwarded emails and pass them around, in order to disrupt whatever’s on the other end. Schools, council meetings, recovery groups, and churches are the usual targets, because all of them publish.

    The FBI has warned about exactly this since 2020, when it documented unidentified people disrupting video meetings with pornographic imagery, hate images, and threats. Its first two recommendations were plain: don’t make meetings public, and don’t post the link on unrestricted public social media.

    That’s the fix. The rest of this is how to do it without making it hard for an eighty-year-old to attend Bible study.

    You have three tools for controlling entry, and you don’t need all three at once.

    A waiting room. Everyone who clicks the link lands in a holding area and a host lets them through. This is the single most valuable setting in this article, and it’s on by default in most platforms now. For a group of twenty, admitting people takes fifteen seconds and you recognize every name.

    A passcode, required to join and separate from the link. Fine for a recurring small group; less useful for anything published widely, since it travels with the link.

    Registration. Attendees give a name and email in advance and receive their own personal join link. This is the right choice for a funeral. It takes the family two minutes to share a registration page with relatives, and it makes the guest list a known quantity on the hardest morning of their lives.

    Alongside that, three habits:

    Use a fresh link for anything sensitive — a funeral, a board meeting, a care group. Never the standing Sunday room. A one-off link is a one-off exposure.

    Don’t publish the link where it can be harvested. Put a button on your website behind a click-through or a short form, rather than pasting the raw meeting address into a public page, a printable bulletin, or a Facebook post. For a congregation, email and text is enough.

    Separate broadcasting from meeting. This is the biggest structural improvement most churches can make. A Sunday service doesn’t need to be a meeting — nobody in the congregation needs a microphone. Stream it to YouTube or Facebook instead, where viewers can only watch, and reserve the interactive platform for small groups where you actually want people talking. Half this problem disappears the moment the service stops being a room anyone can walk into.

    Take away the tools before anyone needs them

    Every disruption uses a capability the meeting handed out by default. Turn them off ahead of time, in your account settings — not in each individual meeting, where they’ll be forgotten. Menus change every few months, so here they’re described by what they do:

    Only the host can share their screen. The one that matters most. Screen sharing is how an image gets onto everyone’s display at once, and no participant needs it during a service. In a small group the leader can grant it for a moment when it’s needed.

    Turn off annotation — the tool that lets participants draw on whatever is being shared. It exists for classrooms. In these incidents it’s used to draw obscenities over a hymn slide.

    Turn off participant renaming. Renaming is how someone joins as “Pastor Dan,” or as something vile that then sits in everyone’s participant list.

    Then four smaller ones: mute participants on entry; in large gatherings, prevent them unmuting themselves; turn off private chat and file transfer; and don’t allow people to join before the host, because an unattended room is an empty stage.

    Name a second person whose only job is to watch

    This is the recommendation most likely to be skipped, and the one that actually saves a funeral. The person running the camera and audio cannot also moderate — their hands and attention are already committed, and in an incident the seconds spent hunting for the right menu are the seconds that do the damage.

    So name a second person, a volunteer sitting anywhere, even at home, signed in as a co-host — a role you assign that grants the ability to mute, remove, and lock. Their whole job is to watch the participant list and the chat.

    Give them three things: co-host permission, granted the moment the meeting opens rather than in the middle of an incident — Zoom, for one, only lets you promote a co-host once the meeting is running, so make it the first thing you do; a printed card with the four actions below; and explicit authority. Say that last one out loud: you don’t need to ask anyone. Remove first, explain later. Volunteers hesitate because they’re afraid of removing the wrong person. Removing a confused church member by mistake costs you an apology. Hesitating costs a family a funeral.

    Then practice once, for five minutes, in an empty meeting: have someone join and have the moderator remove them. Muscle memory is the point.

    The thirty-second response

    Print this and tape it to the sound desk.

    1. Mute everyone. There is a mute all control, and it’s the fastest way to stop audio. Do it first — sound reaches more people than an image does.

    2. Stop the screen share. A host or co-host revoking participants’ screen-share permission in the security controls ends a share in progress and clears the image from every screen at once. On Zoom, a single suspend participant activities control does that, mutes everyone, and locks the meeting together.

    3. Remove and report. Removing a participant takes two clicks from the participant list, and most platforms put a report option alongside it that ejects them and sends the account to the platform’s trust and safety team. Use report, not just remove — it gives the platform a record.

    4. Lock the meeting. Once the disruptors are out, locking keeps anyone new from entering. Latecomers are shut out for a few minutes; an acceptable trade.

    And for a stream, cut to a holding card. Keep a static image one keystroke away before every service — the church logo, or a slide reading We’re experiencing a technical difficulty and will return shortly. Switching to it is a calm, defensible act that buys you sixty seconds. Watching an operator scramble on camera is not.

    When it’s over, end the meeting entirely rather than continuing in it.

    Comments and chat on YouTube and Facebook

    Streaming instead of meeting solves the intrusion problem but introduces a smaller one: the comment stream running down the side of your service. Those controls are separate.

    On YouTube, live chat moderation lives in your channel’s community settings. Use three things: a blocked-words list, which blocks any live chat message containing terms you specify — putting the obvious slurs in it is a fifteen-minute job that runs forever; the filter that holds potentially inappropriate messages for review; and named moderators, channel roles letting trusted volunteers remove messages and hide users during a stream without having your password. On Facebook, page moderation works the same way: a profanity filter with adjustable strength, a custom blocked-words list, and a way to give trusted volunteers moderation access so they can hide comments and ban accounts without your password.

    On both, “hide” beats “delete” — a hidden comment stays visible to whoever wrote it, so they don’t immediately notice and repost.

    And the simplest control of all: turn live chat off for services where it adds nothing. Turn it on for the Wednesday study, where conversation is the point, and off on Sunday.

    Afterward: the part that isn’t technical

    If it happens, the technology stops mattering within two minutes and the pastoral work begins.

    Name it out loud, immediately. Don’t push through as if nothing occurred. When you come back on, say plainly: Someone deliberately disrupted our service. That was an attack on us, it was nobody’s fault here, and it’s over now. Silence lets people assume it was somehow the family’s doing, or the church’s negligence.

    Go to the family that day, in person. Not by email. Say clearly that this was done to them by strangers who target funerals precisely because they are tender, that it says nothing about their mother or their church, and that you are sorry. Ask what they want done about the recording — usually the answer is delete it, and be ready to say yes immediately. Take it down in the meantime; you can always restore it, and you can’t unshow it.

    Tell the volunteer it wasn’t their fault, and mean it. The person at the laptop will carry this longer than anyone but the family, and will consider quitting. They weren’t trained, weren’t equipped, and the settings were not their decision.

    Say something to the congregation in the next communication: what happened, what you’ve changed, who to talk to if they’re shaken. Recovering trust here depends far more on visible correction than on explanation.

    And report it, because this is not merely rude behavior. The Department of Justice has stated plainly that hijacking a teleconference can be charged as a state or federal crime, listing possible charges including disrupting a public meeting, computer intrusion, using a computer to commit a crime, hate crimes, fraud, and transmitting threatening communications, with penalties including fines and imprisonment.

    Report it three places: the platform, using the in-meeting report function while it’s happening if you can, since that preserves account data on their side; the FBI at ic3.gov, with the date, time, and display names used; and local police, particularly if there were threats, if the content involved children, or if the disruption was religiously or racially targeted. Ask whether it should be reported as a hate crime — in many places, targeting a religious service changes the classification.

    Before deleting anything public, save what you have offline: screenshots of the participant list, the chat log, and the recording.

    What to do this week

    Open your video platform’s account settings — not one meeting’s, the account’s — and set four things: waiting room on, screen sharing host-only, annotation off, renaming off. Ten minutes, once, for every meeting you will ever hold.

    Then name your moderator. Text one reliable volunteer, ask them to be co-host on Sunday, and send them the four-step card: mute all, stop the share, remove and report, lock the meeting. Tell them they have authority to act without asking.

    That’s twenty minutes, and it’s the difference between ninety seconds and thirty years.

    Wondering what else is sitting unlocked? MissionDefend’s free assessment asks plain questions about your accounts, your member data, your email, and your online giving, then returns a baseline score and a ranked list of what to close first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Bureau of Investigation, Boston Division, FBI Warns of Teleconferencing and Online Classroom Hijacking During COVID-19 Pandemic; U.S. Department of Justice, Eastern District of Michigan, Federal, State, and Local Law Enforcement Warn Against Teleconferencing Hacking During Coronavirus Pandemic.